The attackers exploited two vulnerabilities simultaneously, enabling them to artificially increase their balance

A bug in the Balancer protocol code cost the project $120 million: a detailed overview of the hack

07.11.2025

498

4 min

On November 3, 2025, the decentralized protocol Balancer v2, which is used for exchanging cryptocurrencies without intermediaries, was subjected to a large-scale attack. Several blockchains and related projects were affected. Total losses are estimated at approximately $120 million. This has become one of the most high-profile incidents in decentralized finance (DeFi) over the past year. GetBlock AML Research publishes a detailed overview of what happened.

Why did this happen?

Balancer is a system in which users can exchange tokens or contribute them to a common “liquidity pool” (fund reserve). In return, they receive special tokens — BPT — which show their share in this reserve.

In one part of the code responsible for calculations, a rounding error occurred. This led to microscopic price discrepancies during multiple exchanges — invisible under normal conditions, but if repeated many times, they could yield huge profits.

The hacker took advantage of this. He made a series of small exchanges where these “rounding errors” accumulated, and as a result, he was able to artificially increase his balance in the system. Later, he withdrew these funds as if they were “legally earned.”

How the attacker operated

  • First, the hacker exchanged his BPT tokens for other assets from the pool to reduce the total reserve.
  • Then he made numerous small exchanges between tokens, creating accumulated errors in the calculations.
  • After that, he exchanged the assets back into BPT — and each time received slightly more than he gave.
  • He repeated these operations multiple times until he accumulated significant funds.
  • In the end, he withdrew his profits using the standard withdrawal function, which is why his actions were initially mistaken for a normal transaction.
  • Simply put, he created money “out of thin air” by exploiting a software vulnerability in the protocol’s mathematics.

What happened to the stolen money

After the attack was completed, the stolen assets began to move across different networks and wallets to make them difficult to track.

The main address of the attacker: 0xaa760d53541d8390074c61defeaba314675b8e3f.

He received profits in the form of osETH tokens, USDC, and other assets. These assets were transferred to another wallet: 0xf19fd5c683a958ce9210948858b80d433f6bfae2.

Withdrawal of assets from the Balancer protocol to the attackers’ address

Withdrawal of assets from the Balancer protocol to the attackers’ address

There, the hacker combined all the funds, exchanged some of the tokens for ETH and WETH, and sent some to other networks. Before the attack, the hacker replenished their wallets through Tornado Cash, a service that hides the origin of cryptocurrencies. This is a common practice in money laundering.

Scheme for withdrawing stolen assets. Visualization: MistTrack

Scheme for withdrawing stolen assets. Visualization: MistTrack

The entire chain of transactions shows that the attacker carefully planned the path for withdrawing the money, acting through several networks and exchange platforms.

How developers and the community reacted

Balancer developers quickly activated emergency protection measures:

  • All active pools were frozen to prevent further losses.
  • The creation of new pools was temporarily suspended.
  • Rewards and bonuses (emissions) for affected pools were suspended.
  • Large investors (such as Crypto.com and Ether.fi) managed to withdraw more than $1,8 million.
  • Some of the stolen assets were recovered through “white-hat hackers” and security services. For example, approximately $19 million in osETH tokens and some other assets were returned.
  • Some blockchains associated with Balancer have temporarily suspended operations to prevent the attack from spreading.

What now

At the time of the last update, the Balancer team, together with developers, exchanges, and independent experts, continues to work on returning the funds.

While some of the assets are frozen at various addresses and exchanges, technical and legal analysis is underway.

The developers promise to publish an official report on the incident later, explaining in detail the reasons for the vulnerability and presenting protective measures to prevent this from happening again.

Subscribe to Getblock Magazine and stay up to date with the latest news from the world of cryptocurrencies and the digital economy